Executive brief
OpenSSL is a widely used security library that provides encryption and secure communication tools for applications. A vulnerability exists in how it handles password-protected encrypted messages (CMS). An attacker can send a specially crafted message that causes the application to crash, leading to a denial of service. This issue does not risk the exposure of sensitive data or passwords.
Technical details
A heap out-of-bounds read exists in the kek_unwrap_key() function of OpenSSL's Cryptographic Message Syntax (CMS) implementation. The vulnerability occurs during password-based decryption (RFC 3211 / PWRI key unwrap) when an attacker specifies a stream-mode cipher in the keyEncryptionAlgorithm OID. Because the implementation's length checks assume a block cipher, a stream cipher bypasses these guards, causing the key unwrapping function to read 7 check-bytes from a buffer that is too small. This can result in an application crash (Denial of Service) if the buffer borders an unmapped memory page. No password knowledge is required as the over-read occurs before authentication. FIPS modules are not affected.
Affected products
- OpenSSL Foundation OpenSSL All versions using CMS password-based decryption (excluding FIPS modules)
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
References
- https://github.com/openssl/security/commit/05b066366842f930fadd9a6e94df98030af431bb
- https://github.com/openssl/security/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0
- https://github.com/openssl/security/commit/715349a1d7c6db970e6815dafb90915f07307f98
- https://github.com/openssl/security/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26
- https://github.com/openssl/security/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6
- https://openssl-library.org/news/secadv/20260609.txt